dniel/forwardauth:latest container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of dniel/forwardauth
dniel/forwardauth:latest resolved to f67129ea1c64, scanned 14 Sept 2026: 170 findings, 6 critical, 4 on KEV; deployed by 1 chart, among them forwardauth.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
170 distinct on this digest
Findings for digest f67129ea1c64 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-4j3c-42xv-3f84 | tomcat-embed-core | 9.0.107 |
| Medium | GHSA-h2fw-rfh5-95r3 | tomcat-embed-core | 9.0.105 |
| Medium | GHSA-9xv2-5v5q-p794 | tomcat-embed-core | 9.0.121 |
| Medium | GHSA-9w3m-gqgf-c4p9 | snakeyaml | 1.32 |
| Medium | GHSA-p22x-g9px-3945 | tomcat-embed-core | 9.0.68 |
| Medium | GHSA-2wrp-6fg6-hmc5 | spring-web | 5.3.34 |
| Medium | GHSA-4jq9-2xhw-jpx7 | json | 20231013 |
| Medium | GHSA-m8p2-495h-ccmh | hibernate-validator | 6.0.18.Final |
| Medium | GHSA-v682-8vv8-vpwr | tomcat-embed-websocket | 9.0.86 |
| Medium | GHSA-c4r9-r8fh-9vj2 | snakeyaml | 1.31 |
| Medium | GHSA-78wr-2p64-hpwj | commons-io | 2.14.0 |
| Medium | GHSA-98wm-3w3q-mw94 | snakeyaml | 1.31 |
| Medium | GHSA-3vqj-43w4-2q58 | json | 20230227 |
| Medium | GHSA-h3x4-894j-xpx5 | tomcat-embed-core | 9.0.121 |
| Medium | GHSA-wxqc-pxw9-g2p8 | spring-expression | 5.2.24.RELEASE |
| Medium | GHSA-gcx9-497g-6cp6 | tomcat-embed-core | 9.0.121 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-w37g-rhq8-7m4j | snakeyaml | 1.32 |
| Medium | GHSA-hh3j-x4mc-g48r | tomcat-embed-core | 9.0.29 |
| Medium | GHSA-xf96-w227-r7c4 | spring-boot-autoconfigure | 2.5.15 |
| Medium | GHSA-gx5v-xp9w-j4cg | tomcat-embed-core | 9.0.118 |
| Medium | GHSA-rmrm-75hp-phr2 | hibernate-validator | 6.0.20.Final |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | no fix listed |
| Low | GHSA-vmq6-5m68-f53m | logback-classic | 1.2.13 |
| Low | GHSA-vmq6-5m68-f53m | logback-core | 1.2.13 |
| Low | GHSA-g8pj-r55q-5c2v | tomcat-embed-core | 9.0.81 |
| Low | GHSA-7v6m-28jr-rg84 | hibernate-validator | 6.2.0.CR1 |
| Low | GHSA-cm59-pr5q-cw85 | spring-boot | 2.2.11.RELEASE |
| Low | GHSA-564r-hj7v-mcr5 | spring-expression | 5.2.23.RELEASE |
| Low | GHSA-fv25-8xcx-gqjc | tomcat-embed-core | 9.0.118 |
| Low | GHSA-23hv-mwm6-g8jf | tomcat-embed-core | 9.0.106 |
| Low | GHSA-563x-q5rq-57qp | tomcat-embed-core | 9.0.116 |
| Low | GHSA-hhhw-99gj-p3c3 | snakeyaml | 1.31 |
| Low | GHSA-mgvc-8q2h-5pgc | spring-boot-starter-actuator | no fix listed |
| Low | GHSA-5mp6-jrq3-r938 | tomcat-embed-core | 9.0.118 |
| Low | ALPINE-CVE-2019-1563 | openssl | 1.1.1d-r0 |
| Low | GHSA-x4m4-345f-5h5g | tomcat-embed-core | 9.0.117 |
| Low | GHSA-jjfh-589g-3hjx | spring-boot-actuator | 2.7.18 |
| Low | GHSA-fpj8-gq4v-p354 | tomcat-embed-core | 9.0.113 |
| Low | GHSA-hgrr-935x-pq79 | tomcat-embed-core | 9.0.110 |
| Low | GHSA-rc42-6c7j-7h5r | spring-boot | no fix listed |
| Low | GHSA-r5w3-xv2f-j59q | spring-expression | no fix listed |
| Low | ALPINE-CVE-2021-23839 | openssl | 1.1.1j-r0 |
| Low | GHSA-2rmj-mq67-h97g | spring-web | 5.3.38 |
| Low | ALPINE-CVE-2019-1547 | openssl | 1.1.1d-r0 |
| Low | GHSA-9m3c-qcxr-9x87 | tomcat-embed-core | 9.0.116 |
| Low | GHSA-775g-4xr8-78h8 | spring-expression | no fix listed |
| Low | ALPINE-CVE-2020-28928 | musl | 1.1.22-r4 |
| Low | GHSA-x83m-pf6f-pf9g | hibernate-validator | 6.2.0.Final |
| Low | GHSA-pr98-23f8-jwxv | logback-core | 1.3.15 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| forwardauthdniel | 2.0.13 | latest | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.